Retour à la veille

CVE-2026-100866

Publié : 27 septembre 2026
Modifié : 27 septembre 2026
Lien officiel NVD
Score CVSS
3.3
LOW

Description détaillée

onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, allowing terminal escape sequence injection. Attackers can embed ANSI/OSC escape sequences in project manifest version and name fields to manipulate terminal output, rewrite window titles, hide text, or trigger emulator-specific behavior when victims run onefetch.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Références et Patchs